CSR Generation: Microsoft IIS 7.x
Generating a Certificate Signing Request (CSR) using Microsoft IIS 7.x
To generate your CSR, you will need to log in to your server and use the following instructions:
- Click the 'Start' menu. Select 'Administrative Tools', then 'Internet Information Services (IIS) Manager'.
- Click the server name.
- In the menu, click the 'Server Certificates' button in the 'Security' section.
- On the right-hand-side, click the 'Create Certificate Request...' Action. This will begin the Request Certificate Wizard.
- Fill out your information. The Common name is where you should enter the fully qualified domain name of the website you require the certificate for. For wildcard certificates, this is in the format *.mydomain.com. Click 'Next'.
- Leave the 'Cryptographic service provider' as default. The 'Bit length' can be changed, we recommend a minimum of 1024-bit, and 2048-bit where possible. Click 'Next'.
- Choose a path and filename to save the CSR. Click 'Finish'.
- Your CSR is now generated. Open the 'certreq.txt' file with a text-editor and copy and paste the contents into the enrollment form when requested.
EV certificates require a minimum of a 1024-bit keysize if valid before 2011, and 2048-bit if they are valid into 2011. We recommend that a 2048-bit keysize is the minimum used for all certificates.